From ff8b8a10f24b77363539b8fb531907c963d98045 Mon Sep 17 00:00:00 2001 From: Gregor Kleen Date: Mon, 15 Nov 2021 23:46:21 +0059 Subject: vidhar: ... --- hosts/vidhar/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/hosts/vidhar/default.nix b/hosts/vidhar/default.nix index 45953d93..495e011d 100644 --- a/hosts/vidhar/default.nix +++ b/hosts/vidhar/default.nix @@ -95,7 +95,7 @@ ip46tables -F nixos-fw-forward 2> /dev/null || true ip46tables -X nixos-fw-forward 2> /dev/null || true - ip46tables -N nixos-fw-forward 2>/dev/null || true + ip46tables -N nixos-fw-forward ip46tables -A nixos-fw-forward -i eno1 -j ACCEPT ip46tables -A nixos-fw-forward -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT ip6tables -A nixos-fw-forward -p icmpv6 --icmpv6-type redirect -j nixos-fw-log-refuse @@ -110,7 +110,7 @@ ip46tables -t nat -F nixos-fw-postrouting-nat 2>/dev/null || true ip46tables -t nat -X nixos-fw-postrouting-nat 2>/dev/null || true - ip46tables -t nat -N nixos-fw-postrouting-nat 2>/dev/null || true + ip46tables -t nat -N nixos-fw-postrouting-nat iptables -t nat -A nixos-fw-postrouting-nat -o dsl -j MASQUERADE ip46tables -t nat -A POSTROUTING -j nixos-fw-postrouting-nat @@ -120,7 +120,7 @@ ip46tables -t mangle -F nixos-fw-postrouting-mangle 2>/dev/null || true ip46tables -t mangle -X nixos-fw-postrouting-mangle 2>/dev/null || true - ip46tables -t mangle -N nixos-fw-postrouting-mangle 2>/dev/null || true + ip46tables -t mangle -N nixos-fw-postrouting-mangle ip46tables -t mangle -A nixos-fw-postrouting-mangle -o dsl -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu ip46tables -t mangle -A POSTROUTING -j nixos-fw-postrouting-mangle -- cgit v1.2.3